7.5
CVSSv3

CVE-2022-23833

Published: 03/02/2022 Updated: 22/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in MultiPartParser in Django 2.2 prior to 2.2.27, 3.2 prior to 3.2.12, and 4.0 prior to 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django

fedoraproject fedora 34

fedoraproject fedora 35

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1004752 python-django: CVE-2022-22818 CVE-2022-23833 Package: python-django; Maintainer for python-django is Debian Python Team <team+python@trackerdebianorg>; Source for python-django is src:python-django (PTS, buildd, popcon) Reported by: "Chris Lamb" <lamby@debianorg> Date: Tue, 1 Feb ...
Several security issues were fixed in Django ...
Several security issues were fixed in Django ...
Synopsis Moderate: Red Hat OpenStack Platform 1624 (python-django20) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-django20 is now available for Red Hat OpenStackPlatform 1624 (Tr ...
Synopsis Moderate: Satellite 611 Release Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Satellite 611 Description Red Hat Satellite is a systems management tool for Linux-basedin ...
Synopsis Important: Red Hat OpenStack Platform 1619 (python-django20) security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-django20 is now available for Red Hat OpenStackPlatform 1619 ( ...
Multiple security issues were found in Django, a Python web development framework, which could result in denial of service, SQL injection or cross-site scripting For the stable distribution (bullseye), these problems have been fixed in version 2:2228-1~deb11u1 We recommend that you upgrade your python-django packages For the detailed security ...
An issue was discovered in MultiPartParser in Django 22 before 2227, 32 before 3212, and 40 before 402 Passing certain inputs to multipart forms could result in an infinite loop when parsing files ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2808 python-django 3210-1 402-1 Unknown Fixed ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Django: CVE-2022-23833: Denial-of-service possibility in file uploads <!--X-Subject-Header-End--> <!--X-Head-of-Message--> F ...